icacls输出详解

icacls preserves the canonical order of ACE entries as:

Explicit denials
Explicit grants
Inherited denials
Inherited grants
Perm is a permission mask that can be specified in one of the following forms:

A sequence of simple rights:
F (full access)
M (modify access)
RX (read and execute access)
R (read-only access)
W (write-only access)
A comma-separated list in parenthesis of specific rights:
D (delete)
RC (read control)
WDAC (write DAC)
WO (write owner)
S (synchronize)
AS (access system security)
MA (maximum allowed)
GR (generic read)
GW (generic write)
GE (generic execute)
GA (generic all)
RD (read data/list directory)
WD (write data/add file)
AD (append data/add subdirectory)
REA (read extended attributes)
WEA (write extended attributes)
X (execute/traverse)
DC (delete child)
RA (read attributes)
WA (write attributes)
Inheritance rights may precede either Perm form, and they are applied only to directories:

(OI): object inherit-子文件继承父文件夹权限
(CI): container inherit
(IO): inherit only
(NP): do not propagate inherit
(I): permission inherited from parent container

(I) “Inherited”: This ACE was inherited from the parent container.
(OI) “Object inherit”: This ACE will be inherited by objects placed in this container.
(CI) “Container inherit”: This ACE will be inherited by subcontainers placed in this container.
(IO) “Inherit only”: This ACE will be inherited (see OI and CI), but does not apply to this object itself.
(NP) “Do not propagate”: This ACE will be inherited by objects and subcontainers one level deep – it will not apply to things inside subcontainers.

For the file system, “container” means a folder and “object” means a file, but remember that ACLs can be set on many other kinds of objects, not all of which have a concept of “containers”.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值